Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
P3p
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Ws-Request-Id
X-Amz-Id-2
X-Proxy-Cache
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Akamai-Path-Stats
X-Server
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-Server-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Edge
X-Amz-Server-Side-Encryption
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-B3-TraceId
X-PC
X-Vname
X-TtlSet
Accept-Ch
X-ESI
X-Vcap-Request-Id
X-Content-Type
Xkey
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
X-CST
X-Varnish-TTL
X-Mcache
X-Oneagent-Js-Injection
X-D2id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-VARITI-CCR
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Amz-Rid
Verso
X-GitHub-Request-Id
Cache-Tag
RTSS
X-FastCGI-Cache
X-Powered-By-Plesk
X-Cached
X-Upstream
Service-Worker-Allowed
X-ECACHE
X-Navigation-Version
X-Client-IP
X-Ruxit-Js-Agent
X-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Ac
X-Cnection
Public-Key-Pins
X-Ser
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-SharePointHealthScore
SPRequestGuid
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Server-Name
X-Element-Page-Cache
X-Ttl
X-Country-Code
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-NF-Request-ID
X-NWS-LOG-UUID
X-RateLimit-Remaining
X-Midtier
X-Middleton-Response
Response
X-Goog-Hash
X-Cache-Key
Permissions-Policy
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-For
Access-Control-Request-Method
X-DataDome
Content-MD5
X-Shield-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Powered-CMS
Front-End-Https
Edge-Cache-Tag
AR-ATIME
X-T
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
TP-L2-Cache
X-Recruiting
Nginx-Cache
X-Jurisdiction
TP-Cache
X-HP-Webp
X-HP-Trace-Id
X-RateLimit-Limit
X-Accel-Expires
X-Correlation-Id
TCN
X-Daa-Tunnel
X-Grace
MicrosoftSharePointTeamServices
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Id
X-Mg-S
Filters
X-Hits
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-TEC-API-VERSION
X-HS-Hub-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-Content-Digest
X-Fastly-Request-Id
X-LLID
S
X-Frontend
Server-Name
X-Distributor
X-Amzn-Trace-Id
Cache-Status
X-Protected-By
X-TTL
X-Geo-Country
MS-Author-Via
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
Cross-Origin-Opener-Policy
X-Ezoic-Cdn
X-Ua-Browser
X-Origin-Server
X-Forwarded-Proto
X-Ab
Host
Filterid
Charset
X-B3-Sampled
X-FB-Debug
X-F-Cache
X-Seen-By
X-Git-Hash
X-Page-Id
X-Amz-Meta-S3cmd-Attrs
Realpath
Payment
X-Ratelimit-Reset
Count-Hit
X-Litespeed-Cache
X-ASPNET-VERSION
X-Cache-Age
X-Cluster-Name
X-Erf-Bev-Bev-Is-Generated
X-VCache
Accept-Charset
X-Erf-Bev-Bev
X-Browser-Type
X-DynaTrace
Surrogate-Key
X-Fastcgi-Cache
X-Origin-Cache
Cache-Tags
X-XRDS-Location
X-NGENIX-Cache
X-Rid
Alternate-Protocol
X-Az
Cf-Apo-Via
X-Activity-Id
X-AppVersion
Retry-After
Cleartype
X-Template
X-Webkit-Csp
X-Webkit-CSP
Access-Control-Allow-Method
X-Www-Served-By
X-Varnish-Backend
X-Content
X-Amz-Replication-Status
X-Type
X-TT
X-Tb
X-Node-Name
X-Wix-Request-Id
X-Signature
X-B-Cache
X-B
X-App-Environment
X-DIS-Request-ID
ServerID
X-Upgrade-Enabled
X-Debug
Paypal-Debug-Id
X-Aspnet-Duration-Ms
DC
X-Is-Crawler
X-Flags
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Varnish-Grace
X-Proxy
X-Logged-In
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
Frame-Options
X-Hostname
X-Mobile
X-Envoy-Decorator-Operation
X-Content-Options
X-Source
X-Load-Cache
X-Revision
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-N
Pinterest-Generated-By
X-Cache-Control
Pinterest-Version
X-Pinterest-Rid
Country
X-Contextid
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-User-Agent
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-Whom
X-XRDS-LOCATION
Viewport
X-Cache-Rule
Node
NGB
X-Response-Served-From
X-Original-Request-Id
X-Varnish-Age
Refresh
Access-Control-Request-Headers
X-Mid
X-L-Path
X-Cache-TTL-Remaining
X-Framework
X-Environment-Context
X-Debug-IsPreview
X-Debug-IsConnected
X-Restarts
Content-Disposition
VIX-Pulpo-Upstream-Status
X-Mg-Request-UUID
X-Unique-Id
X-Varnish-Server
X-Cacheable-TTL
X-Jobs
X-G
Url
VIX-Pulpo-Node
X-Cache-Time
Akamai-GRN
Uber-Trace-Id
X-Ratelimit-Remaining
X-Instance
X-NYM-Debug-Backend
X-Cache-Grace
X-Akamai-Request-ID2
X-Adobe-Content
X-Adobe-Loc
X-Page-View
X-Servername
X-Real-IP
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Status
X-Drupal-Cache-Contexts
X-Is-Bot
X-Rendered-As
X-Fastly-Request-ID
Version
X-Content-Powered-By
Countrycode
X-App-Server
X-Debug-Info
X-RemovedCookies
X-ProcessESI
X-Server-ID
X-COUNTRY
X-Http-Reason
X-CDN-Forward
X-APP-VERSION
Protected
X-Tt-Logid
X-IPLB-Instance
X-Hosted-By
Srv
X-IPLB-Request-ID
Accept-Language
Healthy
Liferay-Portal
X-Nginx-Cache-Key
X-Cache-Expired-At
X-Via-JSL
X-Time
X-Device-Type
X-Ratelimit-Limit
X-FW-Type
X-Cache-Hit
X-FW-Static
X-FW-Dynamic
X-Tumblr-Pixel
X-FW-Server
X-Tumblr-User
X-FW-Serve
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-FW-Hash
X-Trace-Id
X-Azure-Ref
Fastcgi-Useragent
Ms-Operation-Id
X-RTag
MS-CV
X-Cache-NGX
Backend
Section-Io-Cache
X-Backend-Name
X-UUID
X-Proxy-Cache-Status
X-Mobile-URL
X-Correlation-ID
X-ECache
X-Cache-Operation
Content-Secure-Policy
Server-Info
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Meta-Geo
X-RN-RSRV
X-Storage
Load-Balancing
X-UPSTREAM-Address
CF-IPCountry
X-HTML-Minification-Powered-By
X-Mode
Azure-Version
X-Section
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
X-Server-W
X-Region
X-ShardId
X-Skip-Cache
X-ShopId
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Format
X-Sorting-Hat-PodId
X-Handled-By
TWC-GeoIP-Country
X-Shopify-Stage
X-VC-Cache
TWC-Privacy
X-Cache-Server
X-Cache-Enabled
X-Labrador-Cache-Channel
X-Locale
X-Forwarded-Host
X-Sql-Count
X-Cache-Host
Webcakes-App-Name
X-Edge-Location
TWC-Device-Class
X-Access
WP-Super-Cache
X-Uri
X-Alternate-Cache-Key
X-Varnish-Cache-Hits
X-Origin-Date
X-PHP-Host
X-PHP-Backend
Eomportal-Instance
Webcakes-Region
X-Akamai-Edgescape
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Varnishpool
TWC-Connection-Speed
S-Rt
X-Varnish-Hostname
Onion-Location
Property-Id
X-Sql-Duration-Ms
Webcakes-App-Version
X-Content-Age
X-Zen-Fury
X-ProxyCache-Key
DB-Nickname
Web-Mar-Node
Locale
X-Proxy-Build
X-Proto
X-Proxied
X-AWS-Id
X-ProxyCache-Status
X-Adobe-Source
X-Routing-Service
X-Timing-Wait
X-UA-Device-Type
X-VWS-Id
X-Zipkin-Id
Selected-Fe
X-ServerID
X-Redis-Cache
Mn-Server-Ip
X-SaId
X-FB-TRIP-ID
X-Request-Time
X-BYPASS-REASON
X-No-Session
X-Say-Cacheable
X-GeoCountry
GEO-INFO
X-Cache-Type
X-Hl-Ver
X-JoinUs
X-LJ-Flow-ID
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Extlb
X-PCL
X-Say-TTL
X-SayCDN-TTL
X-OCL
X-Site-Version
X-GeoCode
X-Generation-Time
X-Tid
X-Datadome
X-Via-Fastly
X-Nginx-Cache
X-Generated-By
X-Xfnlog-Site
X-Cms-Context
Apigw-Requestid
X-Web-Node
X-Cache-Status-Check
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestId
CDN-Uid
X-Varnish-Beresp-Grace
ServedBy
X-URL
CDN-Cache
CDN-CachedAt
X-Debug-Cache
X-Rule
X-Detected-As
X-Cache-Action
X-Dc
X-Ua
X-LSADC-Cache
X-DynaTrace-JS-Agent
X-R9-Blue-Green-Version
Cache-Name
X-Ms-Request-Id
X-Ms-Version
X-FireWall-Port
Cache
SD-X-WS
X-Human
Cross-Origin-Resource-Policy
X-SRV
Xet-Cookie
X-Cache-Tags
Source
X-Amzn-RequestId
X-Amz-Apigw-Id
Cross-Origin-Window-Policy
X-App-Version
X-Cached-By
LB
X-Via-NSCOPI
X-WP-CF-Super-Cache
X-Varnish-Hits
X-RCS-CacheZone
X-WP-CF-Super-Cache-Cache-Control
Xserver
X-MP-GENERATED-AT
WPO-Cache-Message
X-Aspnetmvc-Version
Origin
X-GG-Cache-Date
WPO-Cache-Status
X-GEO
X-Loop
X-TNCMS
X-Cdn
X-IPS-LoggedIn
X-Reqid
X-NewRelic-App-Data
X-Origin-CC
X-Pubstack
X-Origin-TTL
X-AOL-HN
X-Soup
X-Amzn-Remapped-Content-Length
X-Api-Version
Cache-Hits
X-B3-SpanId
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-FW-Version
X-Tumblr-Pixel-2
Rip
From-Origin
X-Service
X-Platform-Server
X-Cluster-Node
Upgrade-Insecure-Requests
Webserver
X-TIME
X-Vgn-Hpd-Reason
X-Varnish-Ttl
X-Origin-Response-Time
X-Ec-GeoHdr
T-Server
Environment
X-Ec-Fail
X-External-Request-Id
X-PBS-Appsvrname
X-Processor
DCR-Decision-By
Surrogated-Key
DCR-Processing-Time-Ms
X-Connection-Hash
Expiry
X-Orig-Expires
Ngx.Var.Host
A
Odigeo-Trace-Id
Lang
X-Developer
Meta-Geo-Continent
X-Destination
MD5-Digest
X-NAPM-TraceId
BehaviorPad-Version
Redirect-Candidate
Rendered-Blocks
X-Owner
X-SRCache-Key
Cdncip
X-D
X-Forwarded-Path
Host-ID
Cdnsip
Sslversion
X-User
X-Application
X-Vdms-Version
X-S
X-Session-Fingerprint
X-VG-WebCache
X-Shop-Environment
X-Served-From
X-S-Cookie
X-Aed
X-Rewrite-Enabled
X-A-Wwc
X-AK-Request-ID
X-ScT
X-Vdms-Path
X-Cache-NE
X-A
X-ARC
X-CSRF-Token
X-Rojux
X-Cluster
X-Tenant
X-A-Dgt
X-A-Dcw
X-A-Dam
X-TIM-N
Xc-Version
X-B-Cookie
HostName
X-BCube-Filmed-By
X-A-Ccd
X-Bc-Bl
X-Request-Host
Fastly-SSL
X-B3-Traceid
OT-Force-Account-Verify
X-Irp-Debug
X-Generated-On
X-Thanos
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Bip
Candidate-Md5Url
X-Provided-By
Machine
X-Forwarded-Site
Mobile-Detection-Method
X-Level-Front-Cache
X-Accel-Buffering
X-Pool
X-Qloud-Router
State
V-Age
Gh-Request-Id
X-Cdn-Origin
Ha-Gx-Prefs
HA-Ipaddr
Is-Eu
IsBot
Kp-EeAlive
X-Auto-Login
X-Core-Mission
X-Developers
X-BBC-Edge-Cache-Status
X-Cdn-Srv
Fastly-SWR
Thinkindot-CacheControl-Type
X-CGP
Traceparent
Thinkindot-Control
X-Cache-Info
X-Branch-Name
Thinkindot-CacheControl
TDXMobile
Fastly-SIE
L
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-DPWN-IS-SECURE
X-Device-Os
L5d-Success-Class
X-Ad-Defer-Variation
Producers
Wxu-Next-Region
NGX
X-DefHash
Wxu-Next-Hostname
Platform
X-Datadog-Parent-Id
NM-Fastcgi-Cache
Origin-CC
Origin-EX
X-Datadog-Trace-Id
X-Clara-WADP
X-Datadog-Sampling-Priority
X-CacheTTL
Release
X-Core-Value
Mail-Subject
Servername
VNS-Age
X-DefElseHash
X-Epic-Correlation-Id
VNS-Cache
Memcached
Req-Svc-Chain
Wxu-Next-Commit
We-Hiring
Server-Host
X-Csrf-Jwt
Vix-Hermes-Req-Id
X-Gzip
X-Rebelmouse-Cache-Control
X-WADP-Cache
X-RateLimit-Remaining-Second
X-WA-Info
X-Viewer-Country
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-VG-TLSProxy
X-Aicache-OS
X-RateLimit-Limit-Second
X-Origin-Time
X-Origin-Expires
X-Origin
X-Parent-Response-Time
X-Esi-Check
X-Dispatcher-Number
X-Proxy-Cache-Info
X-Cache-Id
X-VC
X-Request-URI
X-Cache-Remote
X-Sigma-Backend
X-Sigma
X-SIPLIST1
X-Thinkindot-L3
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-V-Cache
X-Variation
X-Varnish-Remaining-TTL
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-Varnish-CookieINHashed-On
X-S-Maxage
X-Varnish-CookieHashed-On
X-Scale
X-Wix-Viewer-Type
X-Policy
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Host
Adler-Geo
X-Gamma-Serve
X-Gateway-Skip-Cache
X-Gdpr
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Fmm-Version
Cache-Tv-Group
CPC-Age
Country-Code
CPC-Cache
Datacenter
DSUID
Cmstype
Cmsid
X-Fetched-On
X-Fastly-Cache
X-Eu-Site
Cluster
X-GeoIP
X-Geo-Header
X-NodeID
X-Mvc-Supplant-Cachable
X-Loc
X-INCAP-ABP
X-HS-Content-Campaign-Id
X-Nyt-Route
X-GeoIP-City
X-Hash
X-NWS-UUID-VERIFY
X-Minions-Version
X-SplitTest
X-VServer
X-Pod-Name
X-Optimistic-Header
X-NCache
X-Slack-Backend
X-Scheme
X-Planisys-CDN-Rules
X-Clientip
X-Ec-Custom-Error
X-Cache-Bucket
X-Ckpd-Fst-Backend
X-Worker
X-Has-Esi
X-Is-Gdpr
Web-Mar-Region
X-SB
X-Planisys-CDN-Cache
X-Mvc-Supplant-OutputCached
X-JWT-State
X-Planisys-CDN-TTL
Tube-Got-Results
CDCHOST
AKAMAI
Svr
Click-Count-Action-Start
Click-Count-Error
Fastcgi-Cache-TTL
CloudFront-Viewer-Country
Tube-Get-Contents
X-Varnish-Beresp-Ttl
Tube-Got-Eval
Tube-Return
X-Xrds-Location
X-Yandex-Sdch-Disable
Mime-Version
WebServer
X-Hnp-Log
X-Gen-Mode
X-LB-NoCache
X-Block-Status
Sever-Int
Server-Ext
X-Tx-Id
Server-Hostname
User-Cache-Control
X-Udemy-Cache-App-Namespace
X-ZONE
Ec-Rule-Version
X-Tec-Api-Origin
X-Ig-Push-State
X-Tec-Api-Version
X-Microcachable
Pics-Label
Ssr
X-Cache-Date
X-Tec-Api-Root
X-Varnish-Beresp-Status
X-Tb-Optimization-Total-Bytes-Saved
Memory
Canary
Time
X-CMSURLCustom
X-Conf
X-TRACE-ID
Sid
AMP-Access-Control-Allow-Source-Origin
SID
Fastly-Drupal-Html
X-Generated-In
X-Sucuri-Cache
X-Sucuri-ID
X-Refresh
X-ND-Cache
X-Var-Ttl
X-Azure-Ref-OriginShield
X-Via-Popn
X-ATG-Version
X-Via-Popv
X-Cache-Debug
X-Fastly-Backend
X-FC-Vary-Parameters
X-WP-CF-Super-Cache-Active
X-Via-Poph
X-Dmc
X-Edge-Pop
X-Presslabs-Stats
X-Be
X-Akamai-Transformed
Server-ID
X-Servedbyhost
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Newrelic-App-Data
X-CS
Env
X-MSEdge-Features
X-MSEdge-Flight
X-Buckets
X-Trace-ID
X-Cs
X-Fpc
X-Release
X-NC
X-Srv
Fastly-Drupal-HTML
X-EC-Lua
X-Wikidot-Backend
X-Endurance-Cache-Level
X-Wikidot-Static-Cache
X-Esi
X-PX
Magicmarker
X-ID
X-MCACHE
X-Zone
X-TX-ID
X-Tumblr-Pixel-3
GeoIp-Country-Code
CDN
X-DC
True-Client-IP
X-RateLimit-Reset
X-CACHE-AGE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Hyper-Cache
X-M-Log
X-Dispatch
X-M-Reqid
X-Micro-Cache
X-Up
X-Pass-Why
My-App
Pramga
X-Varnish-Beresp-TTL
X-Vc
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-App
C-Via
X-Qnm-Cache
X-Wa
X-Lambda-Id
X-Alfa-Service
X-VCL-Version
X-CACHE-KEY
X-TrackingId
Hostname
X-Edge-Origin-Shield-Region
X-CSRF-TOKEN
N-Cache
X-Edge-Origin-Shield-Bytes
Fastcgi-X-Cache-Version
On-Server
Path
X-Platform
X-Req
X-PAYTM-SRV-ID
X-Vcl-Version
X-Check-Cacheable
X-Air-Pt
True-Client-Ip
Esi-Enabled
Resin-Trace
X-AIR-PT
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
CacheControlHeader
X-Vercel-Cache
X-PERF
X-ApacheServer
X-Vercel-Id
X-HS-Status
X-LB-ID
Tcn
X-TH-Server
GeoIP-Country-Code
X-SD-PageType
X-B3-Spanid
X-Nf-Request-Id
True-Client-Country-4JS
GeoIP-Latitude
Tracecode
X-Node-Id
NtCoent-Length
X-SERVER-NAME
Cache-Key
HIT
Cdn
X-Request-Start
X-API-Version
Proxy-Connection
X-FPC
X-Op-Id-All
X-LAGOON
X-Akamai-Pragma-Client-IP
DT-Hot-News
X-CLOUD-TRACE-CONTEXT
X-WA
XkeyRZ
X-Geo
Section-Origin-Responded
ENV
DynaTrace
X-Render-Time
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Mly-Id
Hit
X-Proxy-CacheRZ
X-Webkit-Csp-Report-Only
Lb
X-HN
X-Via-Ucdn
PFcat
X-Proxy-Upstream
X-Via-CDN
XM
X-Platform-Cluster
X-Platform-Router
X-VarnishDD-TTL
X-Traceid
X-Platform-Processor
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Server-Id
X-Dw-Trace-Id
X-Accel-Expires-Debug
X-ServedByHost
X-Date
X-Edge-POP
WWW-Authenticate
User-Agent
Server-Ttl
X-Datacenter
X-Lb-Id
X-Proxy-Cache-Hk
X-Cdn-Forward
SRV
MIME-Version
YJS-ID
X-Via-PopV
X-LiteSpeed-Cache-Control
X-RAMCache
X-Via-PopH
XServer
X-Via-PopN
X-Li-Pop
X-Cache-Ttl
Geoip-Latitude
X-Li-Fabric
X-Cache-Backend
X-LI-Proto
Dnion-Transfer-Encoding
X-LI-UUID
X-CF-Powered-By
X-Ftr-Request-Id
X-RSL
X-RPS
X-CUA
Yjs-Id
X-TT-LOGID
X-FORWARDED-FOR
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-DW
X-RPM
FSS-Cache
M-TraceId
X-DSS
X-LiteSpeed-Tag
X-DB
X-DI
PICS-Label
X-Response-By
Location
X-Instance-Name
X-Old-Content-Length
Wpo-Cache-Status
Sm-Log-Id
Wpo-Cache-Message
X-Service-Response-Time
X-Request-Url
X-Akamai-Request-ID
Vha6-Origin
X-HITS
X-HA-Backend
X-Nc
X-Fastly-Backend-Reqs
Warning
Ohc-File-Size
X-Akamai-ERRuleID
Nginx-CQVIP
X-Httpd
X-Akamai-ERPolicy
X-UA
X-Litespeed-Cache-Control
X-Mg-Cache
Powered-By
X-Cc-Via
X-Lb-Nocache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Server-IP
X-Fastly-Cache-Hits
X-HostName
X-Cdn-Request-ID
X-B3-ParentSpanId
X-Cache-Ngx
Cdn-Requestid
Cdn-Uid
Cdn-Pullzone
Cdn-Requestcountrycode
Cdn-Edgestorageid
Cdn-Cache
CountryCode
Cdn-Cachedat
Locid
Srvid
Req-ID
X-DataCenter
X-From
X-FL-EDGE
X-UP
X-Webstats-RespID
Uri
X-Snapshot-Date
X-MiniProfiler-Ids
X-Serial
Fastcgi-Cache-Ttl
Ohc-Cache-HIT
X-Moov-T
WZWS-RAY
X-Moov-Xdn-Version